Exorcist Ransomware Campaign
Resumen de la Campana
Ransomware attack group Exorcist launched an aggressive campaign targeting critical infrastructure and enterprise networks between April 20-30, 2026. The group deployed multiple ransomware variants including Exorcist.Ransom (v1.9.5) and Exorcist.Metering, along with payload libraries for lateral movement.
Objetivos
- Exfiltration of critical infrastructure data: Industrial control systems (ICS), power grid databases, energy distribution networks, and transportation protocols.
- Data theft via C2 server at exorcist-c2.mil for encryption and laundering.
- Ransom demand through paid decryption services:
- $150,000 - $300,000 per host in USD (approx. $400-650 per user)
Tacticas
- Hunting for Exorcist Payloads: Attackers used Exploit-DB signatures to identify Exorcist.Ransom and Exorcist.Metering variants.
- Lateral Movement via Metasploit: Use of MSF v4.17.0+ with RCE payloads for network traversal.
- Distributed Denial-of-Service (DDoS): Attackers used Nginx DDoS infrastructure to disrupt critical operations.
- Data Exfiltration: Mass transfer of industrial and operational data via encrypted channels.
- Ransom Demand Distribution: Payment links distributed via email, social media, and technical forums.
Indicadores de Compromiso (IOCs)
| Tipo | Valor/Contexto | |
|---|---|---|
| Ransomware Payloads | - Exorcist.Ransom (v1.9.5) - Microsoft Windows | https://exploit-db.com/metasig/exorcist-ransom/32704 |
| Ransomware Payloads | - Exorcist.Metering (v1.9.5) - Windows / Linux | https://exploit-db.com/metasig/exorcist-metering/32704 |
| C2 Server Domain | - exorcist-c2.mil (TLS 1.3) | N/A - Known C2 infrastructure from Exorcist attack group analysis |
| Distribution Channels | - Email with malicious attachments | Technical forums, social media groups, enterprise email systems |
| Payload Libraries | - Metasploit v4.17.0+ (RCE payload) | N/A - Attack method used to identify payloads and execute them |
| Attack Timeline | - April 20-30, 2026 | Peak attack activity period with multiple phases (initialization, encryption, exfiltration) |
Impacto
The Exorcist campaign resulted in significant data breaches affecting critical infrastructure and enterprise organizations. Attackers targeted industrial control systems which are essential for modern manufacturing, energy distribution, and transportation networks.
Technical analysis revealed multiple attack vectors including payload libraries that allowed attackers to bypass detection methods by using legitimate software versions with modified signatures.